ScreenshotNeo

BlogAI agents

MCP Servers for Searching the Web

Compare MCP web-search servers, connection methods, configuration, security, troubleshooting, and how to choose one for your AI client.

By the ScreenshotNeo team1 October 20268 min read

Short answer: an MCP web-search server is a server that exposes search or retrieval tools to an AI application through the Model Context Protocol. MCP standardizes how the client discovers and calls tools; it does not provide a search index. The server implementation and its provider determine result quality, freshness, authentication, limits and terms.

There is no single official MCP web-search server. The MCP project publishes reference implementations and points developers to the MCP Registry for published servers. Maintained examples include Brave Search, Tavily and Exa, each with a different tool set and connection model.

What an MCP web-search server does

An MCP deployment has three parts:

  1. Host application: Claude, Cursor or another AI application.
  2. MCP client: the component inside the host that connects to servers, discovers tools and sends tool calls.
  3. MCP server: a process or hosted service that exposes tools such as web search, page extraction or crawling and then calls its search provider.

The protocol defines the connection and tool-call shape. It does not rank providers or make returned pages authoritative. Verify important claims against the cited pages and review the server’s permissions before enabling it.

The current MCP specification is dated 2026-07-28. It describes a stateless core, header-based routing, cacheable tool-list results, multi-round-trip requests, authorization hardening and a formal extension framework. Check the specification and the server’s current documentation before copying older session or authentication examples.

Which MCP server can search the web?

Choose by the task you need rather than by the MCP label:

Server Documented capabilities Connection and authentication notes
Brave Search MCP Server Web, local, place, image, video and news search, plus LLM-context and summarization tools. The current repository describes stdio as the default in its 2.x line and HTTP as selectable. Search supports geography, language, result count, freshness and other parameters; some functions depend on the plan.
Tavily MCP Server Search, page extraction, website mapping and crawling. Vendor documentation describes a hosted MCP service, OAuth for supported clients, API-key configuration and a bridge for clients without native remote-MCP support.
Exa MCP Server Web search and page fetching by default; advanced search and agent runs are optional. The repository documents a hosted endpoint, common client configurations and anonymous access with rate limits. OAuth or an API key provides higher limits and Exa Agent access.

These are examples, not a permanent catalog or a quality ranking. The MCP Registry and each provider’s documentation are the source of truth for current availability, pricing and limits.

How to choose a web-search MCP server

  1. Define the retrieval job. Fresh general web search, local results, news, page extraction, site mapping and crawling are different workloads.
  2. List the tools your client can use. Confirm whether your host supports local stdio, remote HTTP, or both.
  3. Check authentication. Identify where API keys or OAuth tokens are stored, which process receives them and how rotation works.
  4. Inspect result provenance. Prefer responses that include the source URL, title, snippet and enough metadata for the model or your application to cite the page.
  5. Check controls and limits. Compare geography, language, freshness, result count, rate limits, crawling depth, page size and plan restrictions.
  6. Review current terms and cost. Provider pricing and quotas change; use the provider’s current pricing page rather than an old example.

Connecting a local MCP server over stdio

Local stdio means the host starts the server as a child process and communicates through standard input and output. This is useful when the provider ships a command-line server or when you want credentials and network access to stay on your machine.

A typical host configuration has this shape:

{
  "mcpServers": {
    "web-search": {
      "command": "YOUR_SERVER_COMMAND",
      "args": ["YOUR_SERVER_ARGUMENTS"],
      "env": {
        "SEARCH_API_KEY": "YOUR_API_KEY"
      }
    }
  }
}

Replace the command, arguments, environment variable and configuration-file location with the instructions for the server you selected. Do not put a real key in a checked-in file. Use the host’s secret store or an environment variable and restrict file permissions.

Stdio checklist

  • Install the exact server version documented by the provider.
  • Run the command manually once and confirm it starts without writing diagnostic text to stdout.
  • Keep logs on stderr so protocol messages on stdout are not corrupted.
  • Open the host’s tool list and verify the expected search tools appear.
  • Make one narrow query before enabling the server for every conversation.

Connecting a hosted MCP server over HTTP

Remote servers communicate over HTTP. The host must support remote MCP or use the bridge documented by the provider. A generic configuration looks like this:

{
  "mcpServers": {
    "remote-search": {
      "url": "https://YOUR_PROVIDER_MCP_ENDPOINT",
      "headers": {
        "Authorization": "Bearer YOUR_TOKEN"
      }
    }
  }
}

The endpoint, header format and OAuth flow are provider-specific. Do not assume that a token issued for one API can be passed through to another MCP server. The MCP security guidance calls token passthrough an anti-pattern: a server should accept only tokens explicitly issued for it.

Calling search tools from an MCP client

After connection, the client normally performs two operations:

  1. Tool discovery: list the tools and their input schemas.
  2. Tool call: send a structured argument object, then read text and structured content returned by the server.

The exact SDK method names depend on the MCP SDK and host. A conceptual call has this shape:

{
  "name": "search",
  "arguments": {
    "query": "MCP web search server",
    "count": 10,
    "freshness": "week"
  }
}

Use the tool schema returned by your connected server for valid names and parameters. Brave, Tavily and Exa expose different capabilities, so a parameter accepted by one server may be rejected by another.

Security controls for production use

MCP tools are model-controlled: the model can decide to invoke them when the host permits it. The tools guidance recommends showing users which tools are exposed and invoked, requesting confirmation where appropriate and allowing a human to deny a call. Apply those controls to search, extraction and crawling tools.

Protect credentials

  • Store keys in environment variables or a secret manager.
  • Use separate keys for development and production.
  • Restrict scopes and rotate keys after a suspected leak.
  • Do not include authorization headers in prompts, logs or returned content.

Control outbound requests

Search servers and OAuth clients can fetch URLs supplied by users, pages or models. The MCP security guidance highlights SSRF risks involving internal services and cloud metadata endpoints. For production deployments, require HTTPS where possible, block private and link-local address ranges, validate redirects, restrict DNS resolution and apply egress controls. Review every URL-fetching or crawling tool separately from ordinary search.

Validate returned content

Search snippets and fetched pages are untrusted input. Treat instructions inside a page as data, not as commands. Preserve source URLs, enforce response-size limits and apply your normal HTML, script and document sanitization rules.

Performance, reliability and cost

  • Latency: a model request can require tool discovery, one or more search calls and page fetches. Limit result counts and fetch only pages needed to answer the question.
  • Caching: cache tool lists and safe, repeatable queries where the provider permits it. Respect freshness requirements and provider terms.
  • Timeouts: use separate deadlines for search and page extraction. Return partial results with source URLs when a secondary fetch fails.
  • Retries: retry transient network failures with exponential backoff and a cap. Do not retry authentication failures or invalid arguments.
  • Rate limits: anonymous or free access may have lower limits. Monitor provider responses and surface a useful message instead of silently dropping sources.
  • Cost: compare the provider’s current plan, per-request rules, extraction charges and crawl limits. No independent cross-provider quality benchmark was established in the reviewed primary documentation.

Common errors and fixes

Error or symptom Likely cause Fix
The server does not appear in the host Wrong configuration path, invalid JSON or unsupported transport. Validate JSON, check the host’s logs and confirm whether it supports stdio, remote HTTP or a provider bridge.
Connection closes immediately The process exits, cannot find its command or writes protocol-breaking output to stdout. Run the command directly, install the documented runtime and send diagnostics to stderr.
401 or 403 response Missing, expired or incorrectly scoped credentials. Regenerate the provider credential, check the expected header or environment variable and verify account access.
Tool not found Tool names differ between servers or the server version changed. Refresh tool discovery and call the exact name and schema returned by the server.
Too many or irrelevant results Query is broad or geography, language, freshness and count are unset. Add specific terms and set the provider’s supported filters.
Page extraction times out The target blocks automated requests, loads slowly or is very large. Use search snippets, set a bounded timeout, skip the page or use a provider’s extraction or crawl tool when appropriate.
Private-network warning A URL points to localhost, an internal address or cloud metadata. Block the request unless that destination is explicitly required and controlled.
Search results contain prompt injection Page content includes instructions aimed at the model. Mark fetched text as untrusted data, isolate it from system instructions and require confirmation before side effects.

Or skip the browser setup

If your agent also needs a visual record of a page, ScreenshotNeo is a screenshot API and MCP server. It accepts one GET request and returns a PNG, JPEG, WebP or PDF. Before capture it accepts consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be turned off. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and the response reports the result in X-Page-Verdict and X-Billed headers.

See the ScreenshotNeo API documentation for the complete option list, including full-page and element capture, device presets, custom CSS and JavaScript, waits, request blocking, cookies, headers, geolocation, PDF settings, caching, signed links, async jobs, bulk capture and usage reporting.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also provides an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. It includes 1,000 screenshots per month free with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

FAQ

Is MCP itself a search engine?

No. MCP standardizes how a client discovers and calls tools. The connected server and search provider supply the index and retrieval behavior.

Should I use stdio or HTTP?

Use stdio for a locally managed process when your host supports it. Use HTTP for a hosted service or when your client supports remote MCP and the provider’s authentication flow.

Are Brave, Tavily and Exa interchangeable?

They overlap on web search but expose different tools, parameters, authentication methods and limits. Select based on whether you need search, extraction, mapping, crawling, local results or news.

Does connecting an MCP server make results trustworthy?

No. Verify important information against returned source pages and keep tool access, credentials and network permissions under review.

Where can I find additional MCP servers?

Use the MCP Registry, then inspect the server’s source, documentation, permissions, authentication and current terms before installation.